cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7947
Views
0
Helpful
18
Replies

ISE Posture - No Policy Server Detected

SecurityJumbo
Level 1
Level 1

Hello guys,

I'm deploying the ISE posture policy and I run into the AnyConnect Posture return "No Policy Server Detected" as shown below.

SecurityJumbo_2-1687656992655.png

 

The switch and machine are able to reach to the ISE ip and dns name.

I created the ISEPostureCFG.xml file and save it at "C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture\"

SecurityJumbo_1-1687656957702.png

 

The ISE AnyConnect Profile

SecurityJumbo_0-1687656921900.png

 

I configured the Client Provisioning, Policy Element, Posture Policy and Policy Set.

Maybe there is a config missing or incorrect, not sure where I start to troubleshoot. Please assist me on this issue.

 

 

18 Replies 18

How many ISE nodes do you have? and does the endpoint use any proxy for web traffic?

SecurityJumbo
Level 1
Level 1

Hey guys, it is only one ISE and direct connection, No Proxy.

No upstream firewall or ACL. No custom portal setting. Using the default one. I will try to change the setting and see if that helps

SecurityJumbo
Level 1
Level 1

Okay, I knew it there is something in the switch. I used another switch and the URL redirecting works fine. 

In that case I would compare the aaa config on both switches, including the redirect ACL, as well as the ensuring the http server is enabled on the switch. If you want to keep the http server enabled on the switch but denying any access to the switch http portal then you can use the following command:

ip http active-session-modules none